CWE-79
47,450 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,450)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mcafee 1Epolicy Orchestrator Jun 17, 2026 Mar 23, 2022 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the...Show more |
1Mcafee 1Epolicy Orchestrator Jun 17, 2026 Mar 23, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by conv...Show more |
1Enhanced Github Project 1Enhanced Github Jun 17, 2026 Mar 22, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter. |
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability. |
1Wpdevart 1Pricing Table Builder Jun 17, 2026 Mar 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
1Accesspressthemes 1Ap Mega Menu Jun 17, 2026 Mar 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. |
The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabil...Show more |
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to...Show more |
1Webnus 1Modern Events Calendar Lite Jun 17, 2026 Mar 21, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scr...Show more |
1Squirrly 1Seo Plugin By Squirrly Seo Jun 17, 2026 Mar 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |
An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administrator can update a worker name. |
1Hexoeditor Project 1Hexoeditor Jun 17, 2026 Mar 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times. |
Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and pr...Show more |
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box. |
TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate. |
A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default. |
An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user. |
1Wp Downloadmanager Project 1Wp Downloadmanager Jun 17, 2026 Mar 18, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_u...Show more |